AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0121 65.7 —
AFFECTED Product Versions Fixed Link Library unspecified —
TIMELINE Aug 4 Reserved by CNA Aug 15 Published (CNA: Wordfence)
926 CVEs published August 15, 2026: 149 critical, 404 high, 26 medium, 11 low; 0 in KEV; 12 with a public exploit reference; 336 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 901 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 5818 | 14623 | 1415 | 2563 |
| KEV catalog size | 1670 | |||
846 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1262 | 2847 | 363 | 1677 | 98 | 0 | 27 | 3 | 0.1 | 7.8 | .0017 | +1247 |
| microsoft | 442 | 1803 | 131 | 1219 | 428 | 8 | 378 | 33 | 1.8 | 7.8 | .0038 | -182 |
| 49 | 461 | 72 | 140 | 228 | 18 | 73 | 5 | 1.1 | 6.5 | .0023 | +48 | |
| red hat | 142 | 364 | 22 | 166 | 158 | 18 | 4 | 0 | 0.0 | 7.1 | .0025 | +126 |
| apple | 2 | 246 | 57 | 68 | 112 | 2 | 93 | 7 | 2.8 | 7.1 | .0027 | +2 |
| canonical | 11 | 14 | 9 | 3 | 2 | 0 | 0 | 0 | 0.0 | 9.9 | .0029 | +11 |
| suse | 5 | 5 | 1 | 2 | 2 | 0 | 0 | 0 | 0.0 | 7.3 | .0022 | +5 |
| android | 0 | 1 | 0 | 1 | 0 | 0 | 16 | 1 | 100.0 | 8.4 | .0171 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 31 | 51 | 9 | 25 | 9 | 0 | 96 | 14 | 27.5 | 7.8 | .0033 | +24 |
| palo alto networks | 12 | 27 | 0 | 1 | 14 | 10 | 14 | 2 | 7.4 | 4.5 | .0019 | +2 |
| fortinet | 7 | 25 | 3 | 6 | 12 | 1 | 28 | 6 | 24.0 | 6.0 | .0051 | -1 |
| sonicwall | 10 | 12 | 3 | 5 | 4 | 0 | 17 | 2 | 16.7 | 7.8 | .0024 | +8 |
| vmware | 0 | 12 | 4 | 7 | 0 | 1 | 21 | 0 | 0.0 | 8.7 | .0044 | 0 |
| netgear | 9 | 9 | 0 | 0 | 5 | 4 | 8 | 0 | 0.0 | 4.3 | .0031 | +9 |
| ivanti | 3 | 8 | 1 | 3 | 0 | 0 | 33 | 5 | 62.5 | 7.9 | .5751 | +3 |
| checkpoint | 1 | 5 | 4 | 1 | 0 | 0 | 3 | 2 | 40.0 | 9.3 | .2062 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 101 | 238 | 45 | 120 | 72 | 1 | 40 | 2 | 0.8 | 7.5 | .0048 | +100 |
| mozilla | 1 | 73 | 42 | 26 | 5 | 0 | 13 | 0 | 0.0 | 9.1 | .0031 | -1 |
| gitlab | 13 | 28 | 0 | 8 | 16 | 2 | 4 | 2 | 7.1 | 5.1 | .0026 | +13 |
| github | 5 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.6 | .0041 | +5 |
| docker | 1 | 4 | 0 | 1 | 3 | 0 | 1 | 0 | 0.0 | 5.7 | .0014 | +1 |
| wordpress | 1 | 4 | 1 | 2 | 1 | 0 | 5 | 2 | 50.0 | 8.8 | .3700 | +1 |
| drupal | 0 | 1 | 1 | 0 | 0 | 0 | 5 | 1 | 100.0 | 9.8 | .8832 | 0 |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0024 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 1113 | 212 | 539 | 304 | 57 | 40 | 3 | 0.3 | 7.6 | .0031 | -1 |
| ibm | 192 | 300 | 61 | 139 | 94 | 6 | 7 | 1 | 0.3 | 7.5 | .0030 | +192 |
| adobe | 60 | 100 | 22 | 51 | 22 | 1 | 75 | 4 | 4.0 | 7.8 | .0036 | +46 |
| progress | 16 | 39 | 11 | 20 | 8 | 0 | 9 | 1 | 2.6 | 8.1 | .0027 | +16 |
| solarwinds | 0 | 20 | 16 | 1 | 1 | 0 | 11 | 4 | 20.0 | 9.1 | .0050 | 0 |
| veeam | 10 | 12 | 3 | 7 | 2 | 0 | 4 | 0 | 0.0 | 8.6 | .0027 | +10 |
| zohocorp | 4 | 7 | 2 | 4 | 1 | 0 | 0 | 0 | 0.0 | 8.8 | .0099 | +4 |
| atlassian | 0 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 16 | 24 | 15 | 0 | 6 | 2 | 26 | 1 | 4.2 | 9.3 | .0209 | +16 |
| siemens | 19 | 20 | 1 | 16 | 1 | 2 | 1 | 0 | 0.0 | 7.3 | .0011 | +19 |
| hikvision | 0 | 7 | 0 | 4 | 2 | 0 | 2 | 1 | 14.3 | 7.2 | .0025 | 0 |
| bosch | 0 | 3 | 0 | 3 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0028 | 0 |
| schneider electric | 0 | 3 | 1 | 2 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0020 | 0 |
| synology | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.3 | .0013 | +1 |
| honeywell | 0 | 1 | 0 | 0 | 1 | 0 | 0 | 0 | 0.0 | 6.9 | .0031 | 0 |
| mitsubishi electric | 0 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.1 | .0013 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| elastic | 48 | 67 | 0 | 13 | 54 | 0 | 3 | 0 | 0.0 | 6.5 | .0027 | +48 |
| siyuan-note | 53 | 60 | 29 | 8 | 23 | 0 | 0 | 0 | 0.0 | 8.8 | .0025 | +53 |
| mongodb | 32 | 58 | 3 | 37 | 16 | 2 | 2 | 0 | 0.0 | 7.1 | .0024 | +32 |
| surrealdb | 0 | 57 | 3 | 26 | 25 | 3 | 0 | 0 | 0.0 | 7.1 | .0025 | -1 |
| zephyrproject | 27 | 49 | 0 | 17 | 26 | 6 | 0 | 0 | 0.0 | 6.5 | .0016 | +26 |
| gitea | 48 | 48 | 7 | 15 | 22 | 4 | 0 | 0 | 0.0 | 6.5 | .0027 | +48 |
| netty | 3 | 44 | 6 | 28 | 9 | 1 | 0 | 0 | 0.0 | 7.5 | .0046 | +3 |
| grafana | 1 | 42 | 3 | 14 | 22 | 3 | 0 | 0 | 0.0 | 6.5 | .0033 | -4 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9931 | 99.9 | 9.8 |
| CVE-2026-63030 | .9560 | 99.9 | 9.8 |
| CVE-2026-34486 | .8293 | 99.6 | 7.5 |
| CVE-2026-16232 | .7330 | 99.4 | 9.3 |
| CVE-2026-60137 | .7310 | 99.4 | 5.9 |
| CVE-2026-0770 | .5688 | 99.0 | 9.8 |
| CVE-2026-62144 | .2062 | 97.3 | 9.1 |
| CVE-2026-9198 | .1735 | 96.9 | 9.8 |
| CVE-2021-27137 | .1649 | 96.7 | 8.1 |
| CVE-2026-15733 | .1354 | 96.1 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .1040 | KEV |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0473 | |
| CVE-2026-47668 | 10.0 | .0434 | |
| CVE-2026-48362 | 10.0 | .0207 | |
| CVE-2026-19188 | 10.0 | .0189 | |
| CVE-2026-73299 | 10.0 | .0121 | |
| CVE-2026-44359 | 10.0 | .0100 | |
| CVE-2026-45618 | 10.0 | .0095 | |
| CVE-2025-71389 | 10.0 | .0093 |
| Vendor | CVEs |
|---|---|
| linux | 1913 |
| oracle | 1108 |
| microsoft | 463 |
| 451 | |
| ibm | 292 |
| red hat | 247 |
| apache | 205 |
| apple | 169 |
| adobe | 75 |
| elastic | 67 |
| Vendor | KEV |
|---|---|
| microsoft | 33 |
| cisco | 14 |
| apple | 7 |
| fortinet | 6 |
| 5 | |
| ivanti | 5 |
| adobe | 4 |
| langflow | 4 |
| solarwinds | 4 |
| synacor | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 66 |
| PyPI | 5 |
| Go | 3 |
| npm | 3 |
| Packagist | 2 |
| crates.io | 2 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-18556 | N-able | 0 |
| CVE-2026-18577 | N-able | 0 |
| CVE-2026-20316 | Cisco | 0 |
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-34486 | Apache Software Foundation | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1732 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1732 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1732 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1732 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1732 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1732 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1732 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1732 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1732 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1732 |
EXPLOIT PUBLISHED — CVE-2020-0618 (Microsoft SQL Server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2021-4034 (polkit). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13712 (Unknown Divi). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-15384 (Unknown Manual Image Crop). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17533 (Unknown All-in-One WP Migration and Backup). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18653 (Unknown WP Directory Kit). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19613 (Unknown ECS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19711 (Unknown Premium Packages). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19712 (Unknown Masteriyo LMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19714 (Unknown Simple JWT Login). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19717 (Unknown CatFolders Document Gallery & PDF Library). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19725 (Unknown WPvivid — Backup, Migration & Staging). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19726 (Unknown Visualizer). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19728 (Unknown Extra Product Options Builder for WooCommerce). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19922 (code-projects Online Shopping System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19925 (SourceCodester Stock Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19927 (OpenBoxes). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19930 (Dolibarr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19933 (DefaultFuction Customer-Relationship-Management-In-C-Project). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19958 (iatsiuk pptr-mcp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19961 (Edimax EW-7478APC). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19962 (Edimax EW-7478APC). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19963 (Edimax EW-7478APC). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19964 (Jij-Inc Jij-MCP-Server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-69414 (Microsoft Malware Protection Engine). Public exploit reference added.
DUE DATE PASSED — CVE-2026-20349 (Cisco Secure Firewall Adaptive Security Appliance (ASA) Software). CISA remediation deadline was August 14, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-72898 (Metabase). CISA remediation deadline was August 14, 2026; still in catalog.
RESCORED — CVE-2020-0618 (Microsoft SQL Server). CVSS 9.8 → 8.8 (NVD).
RESCORED — CVE-2022-21882 (Microsoft Windows 10 Version 1809). CVSS 7 → 7.8 (NVD).
RESCORED — CVE-2022-49363 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2022-49519 (Linux). CVSS 8.8 → 7.8 (NVD).
RESCORED — CVE-2022-49770 (Linux). CVSS 9.8 → 7.8 (NVD).
RESCORED — CVE-2022-49974 (Linux). CVSS 8.8 → 5.5 (NVD).
RESCORED — CVE-2022-50393 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2022-50442 (Linux). CVSS 8.4 → 7.1 (NVD).
RESCORED — CVE-2023-32249 (Linux). CVSS 9.1 → 5.5 (NVD).
RESCORED — CVE-2023-3865 (Linux). CVSS 8.1 → 7.1 (NVD).
RESCORED — CVE-2023-3867 (Linux). CVSS 9.1 → 7.1 (NVD).
RESCORED — CVE-2023-4130 (Linux). CVSS 8.1 → 5.5 (NVD).
RESCORED — CVE-2023-52440 (Linux). CVSS 9.8 → 7.8 (NVD).
RESCORED — CVE-2023-52441 (Linux). CVSS 9.1 → 7.8 (NVD).
RESCORED — CVE-2023-52480 (Linux). CVSS 9.8 → 7 (NVD).
RESCORED — CVE-2026-32590 (Red Hat mirror registry for Red Hat OpenShift 2.0). CVSS 7.1 → 8.8 (NVD).
ENRICHED — CVE-2022-49360 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-49361 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-49364 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-49380 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-49518 (Linux). Received CVSS 7.1 and CPE data from NVD.
ENRICHED — CVE-2022-49520 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-49528 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-49543 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-49833 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-49966 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-49969 (Linux). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2022-49983 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-50009 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-50013 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-50015 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-50016 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-50026 (Linux). Received CVSS 7.1 and CPE data from NVD.
ENRICHED — CVE-2022-50034 (Linux). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2022-50151 (Linux). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2022-50206 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-50223 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-50256 (Linux). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2022-50262 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-50273 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-50316 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-50336 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-50451 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-50479 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-50527 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2022-50535 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2023-32246 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2023-52485 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2023-52506 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2023-52583 (Linux). Received CVSS 5.5 and CPE data from NVD.
926 CVEs published. 25 box scores and 375 table rows below; the remaining 526 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0121 65.7 —
AFFECTED Product Versions Fixed Link Library unspecified —
TIMELINE Aug 4 Reserved by CNA Aug 15 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0098 59.4 —
AFFECTED Product Versions Fixed Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! unspecified —
TIMELINE Jul 30 Reserved by CNA Aug 15 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0080 53.8 —
AFFECTED Product Versions Fixed User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor unspecified —
TIMELINE Jul 15 Reserved by CNA Aug 15 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0076 52.4 —
AFFECTED Product Versions Fixed RapiSafe – Secure Multi File Upload for Contact Form 7 unspecified —
TIMELINE Jul 2 Reserved by CNA Aug 15 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0076 52.1 —
AFFECTED Product Versions Fixed Linux f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e – — Linux 3.7 – 5.10.261
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0076 52.1 —
AFFECTED Product Versions Fixed Linux 8a8633978b842c88fbcfe00d4e5dde96048f630e – — Linux 4.18 – 5.10.261
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0076 52.1 —
AFFECTED Product Versions Fixed Linux c1aa8347e73e4092411fbd96cc59531fb7e76d04 – — Linux 3.19 – 5.10.261
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0074 51.7 —
AFFECTED Product Versions Fixed Linux 82cae269cfa953032fbb8980a7d554d60fb00b17 – — Linux 5.15 – 5.15.212
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0074 51.6 —
AFFECTED Product Versions Fixed Linux 480e3e532e31666a18520a7964bb4095d7a16b9a – — Linux 4.12 – 5.10.261
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0074 51.5 —
AFFECTED Product Versions Fixed Linux 82cae269cfa953032fbb8980a7d554d60fb00b17 – — Linux 5.15 – 5.15.212
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0073 51.4 —
AFFECTED Product Versions Fixed Linux 4949314c7283ea4f9ade182ca599583b89f7edd6 – — Linux 3.3 – 5.10.261
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0073 51.4 —
AFFECTED Product Versions Fixed Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 – — Linux 2.6.12 – 5.10.261
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0073 51.4 —
AFFECTED Product Versions Fixed Linux 473c7dd1d7b59ff8f88a5154737e3eac78a96e5b – — Linux 4.20 – 5.10.261
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0073 51.2 —
AFFECTED Product Versions Fixed Linux c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 – — Linux 2.6.38 – 5.15.212
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0073 51.2 —
AFFECTED Product Versions Fixed Linux db1312dd95488b5e6ff362ff66fcf953a46b1821 – — Linux 6.0 – 6.12.101
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0073 51.2 —
AFFECTED Product Versions Fixed Linux 41c8f70f5a3db7e06179186b6525fd9ee1d7d314 – — Linux 4.14 – 5.15.212
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0072 50.8 —
AFFECTED Product Versions Fixed Linux d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 – — Linux 4.9 – 5.10.261
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0072 50.8 —
AFFECTED Product Versions Fixed Linux 0a5143f2f89cc88d8a3eada8e8ccd86c1e988257 – — Linux 4.20 – 5.10.261
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0072 50.8 —
AFFECTED Product Versions Fixed Linux 460c112e1d887b58b06b56e8e0230058906ff2c3 – — Linux 6.19 – 5.10.261
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0071 50.6 —
AFFECTED Product Versions Fixed Linux 18f84d41d34fa35d0d64bbaea01fe664553ecc06 – — Linux 4.2 – 6.1.178
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0070 50.3 —
AFFECTED Product Versions Fixed Linux 10b4f09491bfeb0b298cb2f49df585510ee6189a – — Linux 5.7 – 5.10.261
TIMELINE Aug 15 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0070 50.3 —
AFFECTED Product Versions Fixed Linux 2a3b791e6e1169f374224d164738e9f7be703d77 – — Linux 2.6.28 – 5.10.261
TIMELINE Jul 30 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0070 50.3 —
AFFECTED Product Versions Fixed Linux 9a05475cebdd6341884b5901e53870be26e65158 – — Linux 3.10 – 5.10.261
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0070 50.3 —
AFFECTED Product Versions Fixed Linux 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349 – — Linux 4.19 – 5.10.261
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0070 50.3 —
AFFECTED Product Versions Fixed Linux 7ea7b4a142758deaf46c1af0ca9ceca6dd55138b – — Linux 3.13 – 5.10.261
TIMELINE Aug 9 Reserved by CNA Aug 15 Published (CNA: Linux)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-72251 | 9.8 | 50.3 | Linux | Linux | — | netfilter: nf_nat_sip: reload possible stale data pointer |
| CVE-2026-72398 | 9.8 | 50.3 | Linux | Linux | — | sctp: add INIT verification after cookie unpacking |
| CVE-2026-74267 | 9.8 | 50.3 | Linux | Linux | — | net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek befor… |
| CVE-2026-72296 | 9.1 | 50.3 | Linux | Linux | — | net: ife: require ETH_HLEN to be pullable in ife_decode() |
| CVE-2026-72231 | 7.5 | 49.7 | Linux | Linux | — | batman-adv: tt: avoid request storms during pending request |
| CVE-2026-72247 | 7.5 | 49.7 | Linux | Linux | — | netfilter: nf_conncount: fix zone comparison in tuple dedup |
| CVE-2026-72409 | 7.5 | 49.7 | Linux | Linux | — | net: mvneta: re-enable percpu interrupt on resume |
| CVE-2026-72502 | 7.5 | 49.7 | Linux | Linux | — | tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) |
| CVE-2026-74282 | 7.5 | 49.7 | Linux | Linux | — | tipc: prevent snt_unacked underflow on CONN_ACK |
| CVE-2026-72234 | 9.8 | 49.6 | Linux | Linux | — | batman-adv: access unicast_ttvn skb->data only after skb realloc |
| CVE-2026-72464 | 7.5 | 49.2 | Linux | Linux | — | xprtrdma: Repost Receive buffers for malformed replies |
| CVE-2026-72014 | 9.8 | 49.2 | Linux | Linux | — | drbd: reject data replies with an out-of-range payload size |
| CVE-2026-72399 | 9.8 | 49.1 | Linux | Linux | — | net: enetc: check the number of BDs needed for xdp_frame |
| CVE-2026-72451 | 9.8 | 49.1 | Linux | Linux | — | xfrm: Fix xfrm state cache insertion race |
| CVE-2026-74281 | 7.5 | 49.0 | Linux | Linux | — | tipc: reject inverted service ranges from peer bindings |
| CVE-2026-72422 | 9.8 | 48.9 | Linux | Linux | — | ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE |
| CVE-2026-72473 | 9.8 | 48.8 | Linux | Linux | — | xprtrdma: Decouple req recycling from RPC completion |
| CVE-2026-72065 | 9.8 | 48.7 | Linux | Linux | — | net: mana: Validate the packet length reported by the NIC |
| CVE-2026-72069 | 9.8 | 48.7 | Linux | Linux | — | locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() |
| CVE-2026-72299 | 9.8 | 48.7 | Linux | Linux | — | tipc: restrict socket queue dumps in enqueue tracepoints |
| CVE-2026-72149 | 7.5 | 48.4 | Linux | Linux | — | dmaengine: tegra: Fix burst size calculation |
| CVE-2026-72465 | 7.5 | 48.4 | Linux | Linux | — | xprtrdma: Sanitize the reply credit grant after parsing |
| CVE-2026-72317 | 9.8 | 48.3 | Linux | Linux | — | SUNRPC: pin upper rpc_clnt across the TLS connect_worker |
| CVE-2026-72381 | 9.8 | 48.3 | Linux | Linux | — | ksmbd: fix use-after-free of fp->owner.name in durable handle owner check |
| CVE-2026-72098 | 9.8 | 48.0 | Linux | Linux | — | dm-verity: fix buffer overflow in FEC calculation |
| CVE-2026-72323 | 9.8 | 47.9 | Linux | Linux | — | ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() |
| CVE-2026-72472 | 9.8 | 47.9 | Linux | Linux | — | nfs: use nfsi->rwsem to protect traversal of the file lock list |
| CVE-2026-72310 | 8.1 | 47.8 | Linux | Linux | — | smb: client: fix overflow in passthrough ioctl bounds check |
| CVE-2026-72366 | 9.8 | 47.8 | Linux | Linux | — | netfs: Fix netfs_create_write_req() to handle async cache object creation |
| CVE-2026-72107 | 8.8 | 47.4 | Linux | Linux | — | dm era: fix out-of-bounds memory access for non-zero start sector |
| CVE-2026-72160 | 8.8 | 47.4 | Linux | Linux | — | ocfs2: reject dinodes with non-canonical i_mode type |
| CVE-2026-72330 | 7.5 | 47.3 | Linux | Linux | — | net/tls: Consume empty data records in tls_sw_read_sock() |
| CVE-2026-72356 | 7.5 | 47.3 | Linux | Linux | — | cifs: Fix missing credit release on failure in cifs_issue_read() |
| CVE-2026-68476 | 9.8 | 47.1 | Linux | Linux | — | ipvs: reload ip header after head reallocation |
| CVE-2026-72041 | 9.8 | 47.1 | Linux | Linux | — | espintcp: use sk_msg_free_partial to fix partial send |
| CVE-2026-72046 | 9.8 | 47.1 | Linux | Linux | — | gve: fix header buffer corruption with header-split and HW-GRO |
| CVE-2026-72137 | 9.8 | 47.1 | Linux | Linux | — | xfrm: nat_keepalive: avoid double free on send error |
| CVE-2026-72185 | 9.8 | 47.1 | Linux | Linux | — | ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() |
| CVE-2026-72217 | 9.8 | 47.1 | Linux | Linux | — | SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing |
| CVE-2026-72221 | 9.8 | 47.1 | Linux | Linux | — | sunrpc: wait for in-flight TLS handshake callback when cancel loses race |
| CVE-2026-72222 | 9.8 | 47.1 | Linux | Linux | — | sunrpc: pin svc_xprt across the asynchronous TLS handshake callback |
| CVE-2026-72348 | 9.1 | 47.1 | Linux | Linux | — | netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop |
| CVE-2026-72373 | 7.5 | 46.9 | Linux | Linux | — | afs: Fix missing NULL pointer check in afs_break_some_callbacks() |
| CVE-2026-72191 | 9.8 | 46.7 | Linux | Linux | — | ntfs3: validate split-point offset in indx_insert_into_buffer |
| CVE-2026-15689 | 9.8 | 46.2 | ABEVERLEY | Dancer2::Plugin::Auth::Extensible | CWE-640 | Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow passw… |
| CVE-2026-72429 | 9.8 | 46.1 | Linux | Linux | — | ipv6: ioam: fix type confusion of dst_entry |
| CVE-2026-74268 | 9.8 | 46.1 | Linux | Linux | — | tcp: clear sock_ops cb flags before force-closing a child socket |
| CVE-2026-72242 | 7.5 | 45.6 | Linux | Linux | — | selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() |
| CVE-2026-72253 | 7.5 | 45.6 | Linux | Linux | — | netfilter: nf_conntrack_sip: validate skb_dst() before accessing it |
| CVE-2026-72254 | 7.5 | 45.6 | Linux | Linux | — | netfilter: nft_fib: reject fib expression on the netdev egress hook |
| CVE-2026-72382 | 8.8 | 45.4 | Linux | Linux | — | ksmbd: reject undersized DACLs before parsing ACEs |
| CVE-2026-72139 | 9.8 | 45.4 | Linux | Linux | — | tcp: defer md5sig_info kfree past RCU grace period in tcp_connect |
| CVE-2026-72220 | 9.8 | 45.4 | Linux | Linux | — | sunrpc: harden rq_procinfo lifecycle to prevent double-free |
| CVE-2026-72393 | 9.8 | 45.4 | Linux | Linux | — | eth: fbnic: don't cache shinfo across skb realloc |
| CVE-2026-72318 | 9.4 | 45.3 | Linux | Linux | — | cifs: validate DFS referral string offsets |
| CVE-2026-72141 | 7.5 | 45.1 | Linux | Linux | — | i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ) |
| CVE-2026-72367 | 8.8 | 45.0 | Linux | Linux | — | iomap: guard io_size EOF trim against concurrent truncate underflow |
| CVE-2026-15965 | 8.8 | 44.9 | sadathimel | MaxUpload – Big File Uploads – Increase Maximum File Upload Size | CWE-434 | MaxUpload <= 1.4.0 - Unauthenticated Arbitrary File Upload via 'resumableFile… |
| CVE-2026-72021 | 8.2 | 45.0 | Linux | Linux | — | ipvs: use parsed transport offset in SCTP state lookup |
| CVE-2026-72100 | 8.8 | 44.0 | Linux | Linux | — | dm-integrity: fix a bug if the bio is out of limits |
| CVE-2026-72421 | 10.0 | 43.7 | Linux | Linux | — | ipv4: fib: Don't ignore error route in local/main tables. |
| CVE-2026-72355 | 9.8 | 43.6 | Linux | Linux | — | netfs: Fix barriering when walking subrequest list |
| CVE-2026-72064 | 9.8 | 43.6 | Linux | Linux | — | net: mana: Sync page pool RX frags for CPU |
| CVE-2026-72417 | 9.8 | 43.6 | Linux | Linux | — | netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() |
| CVE-2026-72442 | 9.8 | 43.6 | Linux | Linux | — | netfilter: flowtable: fix and simplify IP6IP6 tunnel handling |
| CVE-2026-72057 | 8.2 | 43.6 | Linux | Linux | — | net/sched: act_ct: preserve tc_skb_cb across defragmentation |
| CVE-2026-74394 | 9.8 | 43.3 | Linux | Linux | — | RDMA/srpt: fix integer overflow in immediate data length check |
| CVE-2026-73634 | 7.5 | 43.0 | Apache Software Foundation | Apache Struts | CWE-400 | Apache Struts: Unbounded read of a Content Security Policy violation report |
| CVE-2026-72035 | 8.2 | 42.7 | Linux | Linux | — | net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeu… |
| CVE-2026-72320 | 9.1 | 42.0 | Linux | Linux | — | netfilter: nft_lookup: fix catchall element handling with inverted lookups |
| CVE-2026-74279 | 10.0 | 41.8 | Linux | Linux | — | crypto: cavium/cpt - fix DMA cleanup using wrong loop index |
| CVE-2026-74384 | 9.8 | 41.8 | Linux | Linux | — | nvme-multipath: fix flex array size in struct nvme_ns_head |
| CVE-2026-74398 | 9.8 | 41.8 | Linux | Linux | — | ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD |
| CVE-2026-74287 | 9.1 | 41.8 | Linux | Linux | — | sctp: validate embedded address parameter length |
| CVE-2026-74396 | 7.5 | 41.7 | Linux | Linux | — | RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure |
| CVE-2026-72407 | 10.0 | 41.5 | Linux | Linux | — | geneve: validate inner network offset in geneve_gro_complete() |
| CVE-2026-72199 | 9.8 | 41.6 | Linux | Linux | — | ntfs: validate resident index root values on lookup |
| CVE-2026-72200 | 9.8 | 41.6 | Linux | Linux | — | ntfs: detect mapping-pairs LCN accumulator overflow |
| CVE-2026-72201 | 9.8 | 41.6 | Linux | Linux | — | ntfs: validate index entries on reading |
| CVE-2026-72206 | 9.8 | 41.6 | Linux | Linux | — | ntfs: validate index block header more strictly |
| CVE-2026-72207 | 9.8 | 41.6 | Linux | Linux | — | ntfs: not change 0-byte $DATA attribute to non-resident |
| CVE-2026-72208 | 9.8 | 41.6 | Linux | Linux | — | ntfs: add bounds check before accessing EA entries |
| CVE-2026-72209 | 9.8 | 41.5 | Linux | Linux | — | ntfs: validate attribute values on lookup |
| CVE-2026-72210 | 9.8 | 41.6 | Linux | Linux | — | ntfs: fix off-by-one in mapping pairs decoding bounds checks |
| CVE-2026-72211 | 9.8 | 41.6 | Linux | Linux | — | ntfs: grow index root value before reparent header update |
| CVE-2026-72248 | 9.8 | 41.5 | Linux | Linux | — | netfilter: flowtable: support IPIP tunnel with direct xmit |
| CVE-2026-72249 | 9.8 | 41.5 | Linux | Linux | — | netfilter: flowtable: use dst in this direction when pushing IPIP header |
| CVE-2026-72477 | 9.8 | 41.5 | Linux | Linux | — | fs/ntfs3: call _ntfs_bad_inode() when failing to rename |
| CVE-2026-73194 | 9.1 | 41.3 | — | DBI | CWE-1284 | DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an un… |
| CVE-2026-74376 | 9.8 | 41.1 | Linux | Linux | — | md/raid10: reset read_slot when reusing r10bio for discard |
| CVE-2026-74478 | 9.8 | 41.1 | Linux | Linux | — | um: vector: fix use-after-free in vector_mmsg_rx() |
| CVE-2026-72353 | 8.8 | 41.0 | Linux | Linux | — | ntfs: avoid stale runlist element dereference in fallocate |
| CVE-2026-72354 | 8.8 | 41.0 | Linux | Linux | — | ntfs: avoid stale runlist element dereference in MFT writeback |
| CVE-2026-74321 | 7.5 | 41.0 | Linux | Linux | — | btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() |
| CVE-2026-74255 | 9.8 | 40.9 | Linux | Linux | — | tipc: fix UAF in tipc_l2_send_msg() |
| CVE-2026-74406 | 9.8 | 40.4 | Linux | Linux | — | vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). |
| CVE-2026-73193 | 9.8 | 40.3 | — | DBI | CWE-190 | DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit… |
| CVE-2026-68457 | 9.1 | 39.6 | Linux | Linux | — | ksmbd: use opener credentials for FSCTL mutations |
| CVE-2026-19898 | 2.9 | 39.5 | n/a | VictoriaMetrics | CWE-307 | VictoriaMetrics VMAuth Authentication Endpoint main.go requestHandler excessi… |
| CVE-2026-72492 | 8.8 | 39.2 | Linux | Linux | — | ksmbd: fix use-after-free in same_client_has_lease() |
| CVE-2026-72202 | 7.5 | 38.5 | Linux | Linux | — | ntfs: avoid heap allocation for free-cluster readahead state |
| CVE-2026-72203 | 7.5 | 38.5 | Linux | Linux | — | ntfs: skip extent mft records in writeback to prevent deadlock |
| CVE-2026-72186 | 9.1 | 38.5 | Linux | Linux | — | ntfs: make system files immutable to prevent corruption |
| CVE-2026-72188 | 9.1 | 38.5 | Linux | Linux | — | ntfs: sanitize MFT references returned from ntfs_lookup_inode_by_name() |
| CVE-2026-73635 | 7.5 | 38.0 | Apache Software Foundation | Apache Struts | CWE-770 | Apache Struts: Unbounded growth of localized-text caches driven by the reques… |
| CVE-2026-72099 | 7.1 | 38.0 | Linux | Linux | — | dm-integrity: don't increment hash_offset twice |
| CVE-2026-74473 | 9.8 | 37.9 | Linux | Linux | — | vxlan: use pskb_network_may_pull() in route_shortcircuit() |
| CVE-2026-74480 | 9.8 | 37.9 | Linux | Linux | — | net: bridge: stop fast-leave after deleting a port group |
| CVE-2026-74495 | 9.8 | 37.9 | Linux | Linux | — | igbvf: Fix leak in TX DMA error cleanup |
| CVE-2026-74545 | 9.8 | 37.9 | Linux | Linux | — | rtase: fix double free of multi-frag skb on DMA map failure |
| CVE-2026-74476 | 9.1 | 37.9 | Linux | Linux | — | veth: convert frag_list skbs before running XDP |
| CVE-2026-19900 | 8.2 | 37.7 | LB-LINK | X-PRO | CWE-798 | LB-LINK X-PRO shadow hard-coded credentials |
| CVE-2026-19901 | 8.2 | 37.7 | LB-LINK | X-PRO | CWE-259 | LB-LINK X-PRO easycwmp hard-coded credentials |
| CVE-2026-74345 | 9.8 | 37.4 | Linux | Linux | — | RDMA/siw: Fix endpoint/socket association handling |
| CVE-2026-74401 | 9.8 | 37.4 | Linux | Linux | — | dlm: fix add msg handle in send_queue ordered |
| CVE-2026-74309 | 10.0 | 37.2 | Linux | Linux | — | vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler |
| CVE-2026-74361 | 9.8 | 37.2 | Linux | Linux | — | nvme: fix FDP fdpcidx bounds check |
| CVE-2026-74316 | 7.5 | 37.1 | Linux | Linux | — | NFSD: Handle layout stid in nfsd4_drop_revoked_stid() |
| CVE-2026-72420 | 8.8 | 37.0 | Linux | Linux | — | md/raid5: avoid R5_Overlap races while breaking stripe batches |
| CVE-2026-74493 | 9.8 | 37.0 | Linux | Linux | — | net/smc: fix socket use-after-free during link group termination |
| CVE-2026-15303 | 9.8 | 36.8 | sixstorage | 6Storage Rentals | CWE-287 | 6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Par… |
| CVE-2026-74474 | 9.8 | 36.8 | Linux | Linux | — | vxlan: use pskb_network_may_pull() for transmit path header pulls |
| CVE-2026-74523 | 7.5 | 36.7 | Linux | Linux | — | qede: sync udp_tunnel ports outside qede_lock in the recovery path |
| CVE-2026-74550 | 7.5 | 36.7 | Linux | Linux | — | net: do not send ICMP/NDISC Redirects when peer allocation fails |
| CVE-2026-74385 | 7.5 | 36.0 | Linux | Linux | — | nvmet-tcp: check return value of nvmet_tcp_set_queue_sock |
| CVE-2026-19598 | 9.8 | 35.6 | sc0ttkclark | Pods – Custom Content Types and Fields | CWE-863 | Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass… |
| CVE-2026-73046 | 9.3 | 35.5 | siyuan-note | siyuan | CWE-307 | SiYuan before v3.7.4 Authentication Bypass via HTTP Basic Auth |
| CVE-2026-74469 | 8.8 | 34.6 | Linux | Linux | — | sctp: prevent peer transport count overflow |
| CVE-2026-12248 | 6.5 | 34.2 | WPML | WPML Multilingual CMS | CWE-89 | WPML Multilingual CMS <= 4.9.5 - Authenticated (Translator+) SQL Injection vi… |
| CVE-2026-72408 | 10.0 | 33.9 | Linux | Linux | — | geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint |
| CVE-2026-72463 | 9.8 | 33.9 | Linux | Linux | — | xfrm: Fix dev use-after-free in xfrm async resumption |
| CVE-2026-72494 | 9.8 | 33.9 | Linux | Linux | — | RDMA/irdma: Replace waitqueue and flag with completion |
| CVE-2026-74764 | 10.0 | 33.7 | pandora-analysis | pandora | CWE-22 | Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandora |
| CVE-2026-74427 | 9.8 | 33.6 | Linux | Linux | — | afs: Fix netns teardown to cancel the preallocation charger |
| CVE-2026-72029 | 8.8 | 33.5 | Linux | Linux | — | net: wwan: iosm: bound device offsets in the MUX downlink decoder |
| CVE-2026-74490 | 8.8 | 33.6 | Linux | Linux | — | tipc: avoid use-after-free in poll trace queue dumps |
| CVE-2026-74522 | 8.8 | 33.6 | Linux | Linux | — | ksmbd: fix use-after-free in __close_file_table_ids() |
| CVE-2026-19895 | 2.9 | 33.4 | opensourcepos | Open Source Point of Sale | CWE-307 | opensourcepos Open Source Point of Sale Login Endpoint Filters.php index exce… |
| CVE-2026-74475 | 10.0 | 33.0 | Linux | Linux | — | vxlan: use neigh_ha_snapshot() in route_shortcircuit() |
| CVE-2026-18387 | 6.5 | 32.3 | trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | CWE-89 | Groundhogg <= 4.5.14 - Authenticated (Vendor+) SQL Injection via 'tag_query' … |
| CVE-2026-15001 | 8.8 | 32.1 | connectordev | bLoyal: Loyalty & Promotions by bLoyal | CWE-269 | bLoyal: Loyalty & Promotions by bLoyal <= 3.1.611.78 - Authenticated (Subscri… |
| CVE-2026-74269 | 9.8 | 31.1 | Linux | Linux | — | bnxt: fix head underflow on XDP head-grow |
| CVE-2026-74315 | 9.8 | 31.1 | Linux | Linux | — | lockd: Avoid hashing uninitialized bytes in nlm4svc_lookup_file() |
| CVE-2026-74350 | 9.8 | 31.1 | Linux | Linux | — | ocfs2: validate fast symlink target during inode read |
| CVE-2026-16142 | 9.8 | 30.8 | themetechmount | TrueBooker – Appointment Booking and Scheduler System | CWE-639 | TrueBooker <= 1.2.6 - Unauthenticated Account Takeover via Insecure Direct Ob… |
| CVE-2026-74576 | 7.5 | 30.7 | Linux | Linux | — | mm/slab: prevent unbounded recursion in free path with new kmalloc type |
| CVE-2026-72493 | 9.9 | 30.5 | Linux | Linux | — | net: serialize netif_running() check in enqueue_to_backlog() |
| CVE-2026-73043 | 9.4 | 30.3 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 Remote Code Execution via Template Calculation |
| CVE-2026-19897 | 2.9 | 30.1 | mangroup | dtale | CWE-307 | mangroup dtale Login Endpoint auth.py login excessive authentication |
| CVE-2026-74436 | 9.8 | 29.5 | Linux | Linux | — | rxrpc: serialize kernel accept preallocation with socket teardown |
| CVE-2026-72440 | 7.1 | 29.5 | Linux | Linux | — | md/raid1: fix writes_pending and barrier reference leaks on write failures |
| CVE-2026-74556 | 9.8 | 29.0 | Linux | Linux | — | scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer |
| CVE-2026-72438 | 7.5 | 29.0 | Linux | Linux | — | md/raid10: fix writes_pending and barrier reference leaks on discard failures |
| CVE-2026-74428 | 9.8 | 28.2 | Linux | Linux | — | rxrpc: Fix double unlock in rxrpc_recvmsg() |
| CVE-2026-74433 | 9.8 | 28.2 | Linux | Linux | — | rxrpc: Fix UAF in rxgk_issue_challenge() |
| CVE-2026-74425 | 7.5 | 28.1 | Linux | Linux | — | afs: handle CB.InitCallBackState3 requests without a server record |
| CVE-2026-74435 | 7.5 | 28.1 | Linux | Linux | — | rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc |
| CVE-2026-74569 | 9.8 | 27.9 | Linux | Linux | — | netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() |
| CVE-2026-12128 | 5.3 | 27.9 | dotonpaper | Pinpoint Booking System – Version 2 | CWE-20 | Pinpoint Booking System <= 2.9.9.6.8 - Unauthenticated Improper Input Validat… |
| CVE-2026-74572 | 7.5 | 27.6 | Linux | Linux | — | btrfs: zoned: fix deadlock between metadata writeback and transaction commit |
| CVE-2026-16094 | 4.9 | 27.6 | matthiasnordwig | Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms | CWE-89 | Invisible Anti-Spam & CAPTCHA <= 5.1 - Authenticated (Editor+) SQL Injection … |
| CVE-2026-72003 | 8.8 | 27.4 | Linux | Linux | — | wifi: brcmfmac: cyw: fix heap overflow on a short auth frame |
| CVE-2026-15162 | 7.5 | 27.3 | minnpost | Object Sync for Salesforce | CWE-89 | Object Sync for Salesforce <= 2.2.13 - Unauthenticated SQL Injection |
| CVE-2026-74374 | 7.5 | 27.3 | Linux | Linux | — | md/raid1,raid10: fix error-path detection with md_cloned_bio() |
| CVE-2026-74434 | 9.8 | 27.2 | Linux | Linux | — | rxrpc: Don't move a peeked OOB message onto the pending queue |
| CVE-2026-74341 | 8.8 | 27.3 | Linux | Linux | — | wifi: wcn36xx: fix heap overflow from oversized firmware HAL response |
| CVE-2026-72334 | 8.8 | 27.1 | Linux | Linux | — | Bluetooth: ISO: fix malformed ISO_END/CONT handling |
| CVE-2026-18549 | 7.5 | 27.0 | @fastify/multipart | @fastify/multipart | CWE-400 | @fastify/multipart vulnerable to Denial of Service via aborted upload after f… |
| CVE-2026-72233 | 8.8 | 26.9 | Linux | Linux | — | batman-adv: bla: reacquire gw address after skb realloc |
| CVE-2026-72235 | 8.8 | 26.9 | Linux | Linux | — | batman-adv: retrieve ethhdr after potential skb realloc on RX |
| CVE-2026-74429 | 7.5 | 26.8 | Linux | Linux | — | rxrpc: Fix the reception of a reply packet before data transmission |
| CVE-2026-74430 | 7.5 | 26.8 | Linux | Linux | — | rxrpc: Fix ACKALL packet handling |
| CVE-2026-74431 | 7.5 | 26.8 | Linux | Linux | — | rxrpc: Fix potential infinite loop in rxrpc_recvmsg() |
| CVE-2026-72227 | 8.1 | 26.5 | Linux | Linux | — | batman-adv: mcast: avoid OOB read of num_dests header |
| CVE-2026-15341 | 9.8 | 26.2 | rafasashi | User Session Synchronizer | CWE-287 | User Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to… |
| CVE-2026-72121 | 8.8 | 26.2 | Linux | Linux | — | can: bcm: add locking when updating filter and timer values |
| CVE-2026-72124 | 8.8 | 26.2 | Linux | Linux | — | can: isotp: serialize TX state transitions under so->rx_lock |
| CVE-2026-72157 | 8.8 | 26.2 | Linux | Linux | — | net: thunderbolt: Fix frags[] overflow by bounding frame_count |
| CVE-2026-19906 | 6.3 | 25.7 | pkp | pkp-lib | CWE-331 | pkp pkp-lib API Key Generation APIProfileForm.php setData entropy |
| CVE-2026-16586 | 6.5 | 25.7 | contest-gallery | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | CWE-89 | Contest Gallery <= 30.0.6 - Authenticated (Author+) Second-Order SQL Injectio… |
| CVE-2026-72148 | 8.8 | 25.0 | Linux | Linux | — | dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK |
| CVE-2026-68471 | 8.8 | 24.5 | Linux | Linux | — | wifi: ieee80211: validate MLE common info length |
| CVE-2026-72469 | 8.8 | 24.5 | Linux | Linux | — | xprtrdma: Fix ep kref imbalance on ADDR_CHANGE |
| CVE-2026-74521 | 9.1 | 24.2 | Linux | Linux | — | ksmbd: use memcmp() to compare ClientGUIDs |
| CVE-2026-8840 | 5.3 | 24.2 | wpdevart | Booking calendar, Appointment Booking System | CWE-862 | Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorizatio… |
| CVE-2026-72471 | 7.1 | 24.2 | Linux | Linux | — | fs/ntfs3: prevent potential lcn remains uninitialized |
| CVE-2026-73054 | 8.7 | 24.1 | siyuan-note | siyuan | CWE-287 | SiYuan before v3.7.4 Authentication Bypass via WebSocket |
| CVE-2026-19903 | 5.5 | 23.8 | SourceCodester | Online Clothing Store | CWE-552 | SourceCodester Online Clothing Store SQL Database Backup shopping.sql file ac… |
| CVE-2026-15993 | 5.3 | 23.8 | 10web | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | CWE-89 | Form Maker by 10Web <= 1.15.44 - Authenticated (Subscriber+) SQL Injection vi… |
| CVE-2026-74570 | 9.8 | 23.4 | Linux | Linux | — | ntfs: harden runlist realloc size calculations |
| CVE-2026-19896 | 2.9 | 23.4 | mangroup | dtale | CWE-310 | mangroup dtale Flask Session Cookie app.py build_secret_key random values |
| CVE-2026-73045 | 8.7 | 22.8 | siyuan-note | siyuan | CWE-307 | SiYuan before 3.7.4 Brute-Force via authFilePublishAccess |
| CVE-2026-73042 | 9.4 | 22.5 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 Remote Code Execution via Menu Metadata |
| CVE-2026-73052 | 9.4 | 22.5 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names |
| CVE-2026-68472 | 8.1 | 22.4 | Linux | Linux | — | wifi: cfg80211: validate EHT MLE before MLD ID read |
| CVE-2026-16146 | 4.9 | 22.0 | matthiasnordwig | Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms | CWE-89 | Invisible Anti-Spam & CAPTCHA <= 5.1 - Authenticated (Editor+) SQL Injection … |
| CVE-2026-74557 | 7.5 | 21.7 | Linux | Linux | — | scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer |
| CVE-2026-72380 | 8.8 | 21.4 | Linux | Linux | — | xen/pvcalls: bound backend response req_id before indexing rsp[] |
| CVE-2026-68470 | 8.8 | 21.4 | Linux | Linux | — | wifi: mac80211: validate extension-frame layout before RX |
| CVE-2026-18216 | 6.5 | 21.1 | Unknown | Backup Migration | CWE-287 | Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-… |
| CVE-2026-19893 | 2.3 | 21.1 | D-Link | DIR-842 | CWE-266 | D-Link DIR-842 vsftpd vsftpd.conf default permission |
| CVE-2026-73053 | 9.4 | 20.9 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji |
| CVE-2026-14279 | 8.8 | 20.8 | cedcommerce | Wholesale Market | CWE-269 | Wholesale Market <= 2.2.2 - Authenticated (Subscriber+) Privilege Escalation … |
| CVE-2026-15312 | 8.8 | 20.8 | fassionstorage | Propovoice: All-in-One Client Management System | CWE-269 | Propovoice: All-in-One Client Management System <= 1.7.8 - Authenticated (ndp… |
| CVE-2026-72115 | 8.1 | 20.6 | Linux | Linux | — | can: bcm: track a single source interface for ANYDEV timeout/throttle ops |
| CVE-2026-74410 | 8.1 | 20.3 | Linux | Linux | — | wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer |
| CVE-2026-19474 | 7.5 | 20.3 | @fastify/multipart | @fastify/multipart | CWE-459 | @fastify/multipart vulnerable to Denial of Service via temporary file leak on… |
| CVE-2026-74340 | 8.1 | 20.2 | Linux | Linux | — | wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication |
| CVE-2026-74408 | 8.8 | 18.5 | Linux | Linux | — | wifi: ath9k: fix OOB access from firmware tx status queue ID |
| CVE-2026-16145 | 7.2 | 18.6 | matthiasnordwig | Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms | CWE-79 | Invisible Anti-Spam & CAPTCHA <= 5.1 - Unauthenticated Stored Cross-Site Scri… |
| CVE-2026-19899 | 5.5 | 18.2 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System edit_teacher.php sql injection |
| CVE-2026-19919 | 5.5 | 18.2 | code-projects | Online Shopping System | CWE-74 | code-projects Online Shopping System Login login.php sql injection |
| CVE-2026-74300 | 8.8 | 17.8 | Linux | Linux | — | Bluetooth: hci: validate codec capability element length |
| CVE-2026-74411 | 8.8 | 17.5 | Linux | Linux | — | wifi: rtw89: Correct data type for scan index to avoid infinite loop |
| CVE-2026-16611 | 7.5 | 17.4 | Unknown | Product Feed PRO for WooCommerce by AdTribes | CWE-200 | Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuratio… |
| CVE-2026-74508 | 8.8 | 17.1 | Linux | Linux | — | Bluetooth: HIDP: reject frames without a transaction header |
| CVE-2026-74531 | 8.8 | 17.1 | Linux | Linux | — | Bluetooth: hci_conn: hold conn reference in abort_conn_sync() |
| CVE-2026-19905 | 5.5 | 17.1 | Jinher | OA | CWE-74 | Jinher OA attendance_out_approve.aspx sql injection |
| CVE-2026-74767 | 8.7 | 16.9 | pandora-analysis | pandora | CWE-434 | Unbounded DAA Decompression in Pandora Allows Denial of Service via Decompres… |
| CVE-2026-19894 | 2.1 | 16.6 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System viewmedicine.php sql injection |
| CVE-2026-74539 | 8.0 | 16.5 | Linux | Linux | — | Bluetooth: ISO: lock sk in iso_sock_getname |
| CVE-2026-15453 | 6.5 | 16.5 | iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | CWE-89 | KiviCare <= 4.5.1 - Authenticated (Doctor+) SQL Injection via 'searchTerm' Pa… |
| CVE-2026-16080 | 6.5 | 16.5 | fishpie | Image Uploader for Welcart | CWE-89 | Image Uploader for Welcart <= 1.4.6 - Authenticated (Author+) SQL Injection v… |
| CVE-2026-73044 | 9.4 | 16.3 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 Stored Cross-Site Scripting via Column Width |
| CVE-2026-73050 | 9.4 | 16.3 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 Stored XSS via select option color |
| CVE-2026-74488 | 8.8 | 16.2 | Linux | Linux | — | wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames |
| CVE-2026-74540 | 8.8 | 16.2 | Linux | Linux | — | Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp |
| CVE-2026-74541 | 8.8 | 16.2 | Linux | Linux | — | Bluetooth: ISO: clear iso_data always when detaching conn from hcon |
| CVE-2026-13360 | 7.2 | 16.2 | wplegalpages | WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode | CWE-79 | Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Subscriber+) Stored C… |
| CVE-2026-74409 | 8.8 | 15.7 | Linux | Linux | — | wifi: rtw89: add bounds check on firmware mac_id in link lookup |
| CVE-2026-74412 | 8.8 | 15.7 | Linux | Linux | — | wifi: rtw88: fix wrong pci_get_drvdata type in AER handlers |
| CVE-2026-74413 | 8.8 | 15.7 | Linux | Linux | — | wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers |
| CVE-2026-74323 | 8.8 | 15.6 | Linux | Linux | — | wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb() |
| CVE-2026-74535 | 8.8 | 15.5 | Linux | Linux | — | Bluetooth: ISO: avoid deadlocks in iso_sock_timeout |
| CVE-2026-74534 | 8.8 | 15.2 | Linux | Linux | — | Bluetooth: ISO: fix refcounting of iso_conn |
| CVE-2026-74537 | 8.8 | 15.2 | Linux | Linux | — | Bluetooth: ISO: hold sk properly in iso_conn_ready |
| CVE-2026-74538 | 8.8 | 15.2 | Linux | Linux | — | Bluetooth: ISO: lock sk in iso_connect_ind |
| CVE-2026-14433 | 7.2 | 14.9 | vcita | Online Booking & Scheduling Calendar for WordPress by vcita | CWE-79 | Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 - Unauth… |
| CVE-2026-74509 | 8.8 | 14.6 | Linux | Linux | — | Bluetooth: hci_sync: Fix advertising data UAFs |
| CVE-2026-74356 | 7.4 | 14.7 | Linux | Linux | — | vhost: fix vhost_get_avail_idx for a non empty ring |
| CVE-2026-17090 | 6.4 | 14.6 | beaverbuilder | Beaver Builder Page Builder – Drag and Drop Website Builder | CWE-79 | Beaver Builder Page Builder <= 2.10.2.2 - Authenticated (Author+) Stored Cros… |
| CVE-2026-73041 | 9.4 | 14.5 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 Remote Code Execution via PDF Annotations |
| CVE-2026-74507 | 7.1 | 14.2 | Linux | Linux | — | Bluetooth: HIDP: validate numbered report payloads |
| CVE-2026-74575 | 8.8 | 14.0 | Linux | Linux | — | thunderbolt: Prevent XDomain delayed work use-after-free on disconnect |
| CVE-2026-74528 | 8.0 | 14.0 | Linux | Linux | — | Bluetooth: hci_sync: hold conn in hci_past_sync() callback |
| CVE-2026-73631 | 4.3 | 13.7 | Apache Software Foundation | Apache Struts | CWE-567 | Apache Struts: Shared parsing state in the JSON plugin |
| CVE-2026-73632 | 4.3 | 13.7 | Apache Software Foundation | Apache Struts | CWE-567 | Apache Struts: Shared serialization state in the JSON plugin |
| CVE-2026-19918 | 2.1 | 13.8 | SpaceX | Starlink Router Gen 3 | CWE-266 | SpaceX Starlink Router Gen 3 gRPC Management get_status access control |
| CVE-2026-72441 | await | 13.6 | Linux | Linux | — | ieee802154: fix kernel-infoleak in dgram_recvmsg() |
| CVE-2026-72245 | await | 12.9 | Linux | Linux | — | gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path |
| CVE-2026-72056 | await | 12.7 | Linux | Linux | — | net: ena: clean up XDP TX queues when regular TX setup fails |
| CVE-2026-72068 | await | 12.7 | Linux | Linux | — | posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu() |
| CVE-2026-72074 | await | 12.7 | Linux | Linux | — | Input: ims-pcu - fix type confusion in CDC union descriptor parsing |
| CVE-2026-72076 | await | 12.7 | Linux | Linux | — | Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging |
| CVE-2026-72078 | await | 12.7 | Linux | Linux | — | Input: ims-pcu - validate control endpoint type |
| CVE-2026-72079 | await | 12.7 | Linux | Linux | — | Input: ims-pcu - fix use-after-free and double-free in disconnect |
| CVE-2026-72223 | await | 12.7 | Linux | Linux | — | nvdimm/btt: Free arena sub-allocations on discover_arenas() error path |
| CVE-2026-72224 | await | 12.7 | Linux | Linux | — | nvdimm/btt: Free arenas on btt_init() error paths |
| CVE-2026-72307 | await | 12.7 | Linux | Linux | — | mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() |
| CVE-2026-72316 | await | 12.7 | Linux | Linux | — | dm era: fix NULL pointer dereference in metadata_open() |
| CVE-2026-72326 | await | 12.7 | Linux | Linux | — | net/sched: cake: reject overhead values that underflow length |
| CVE-2026-72349 | await | 12.7 | Linux | Linux | — | netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt() |
| CVE-2026-72396 | await | 12.7 | Linux | Linux | — | hwmon: adm1275: Prevent reading uninitialized stack |
| CVE-2026-72414 | await | 12.7 | Linux | Linux | — | net: dsa: sja1105: round up PTP perout pin duration |
| CVE-2026-72447 | await | 12.7 | Linux | Linux | — | sctp: hold socket lock when dumping endpoints in sctp_diag |
| CVE-2026-16541 | 6.5 | 12.6 | Unknown | Simply Schedule Appointments | CWE-200 | Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure… |
| CVE-2026-72073 | await | 12.7 | Linux | Linux | — | mmc: vub300: fix use-after-free on probe failure |
| CVE-2026-74407 | 8.8 | 12.5 | Linux | Linux | — | wifi: ath11k: cancel SSR work items during PCI shutdown |
| CVE-2026-74489 | 8.8 | 12.6 | Linux | Linux | — | wifi: mac80211: fix tid_tx use-after-free on BA session stop |
| CVE-2026-74530 | 8.8 | 12.6 | Linux | Linux | — | Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback |
| CVE-2026-74533 | 8.8 | 12.6 | Linux | Linux | — | Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero |
| CVE-2026-72106 | await | 12.3 | Linux | Linux | — | dm-ioctl: fix a possible overflow in list_version_get_info |
| CVE-2026-72058 | await | 12.1 | Linux | Linux | — | net: ixp4xx_hss: fix duplicate HDLC netdev allocation |
| CVE-2026-72059 | await | 12.1 | Linux | Linux | — | net: wwan: t7xx: destroy DMA pool on CLDMA late init failure |
| CVE-2026-72075 | await | 12.1 | Linux | Linux | — | Input: ims-pcu - fix race condition in reset_device sysfs callback |
| CVE-2026-72081 | await | 12.1 | Linux | Linux | — | scsi: elx: efct: Fix I/O leak on unsupported additional CDB |
| CVE-2026-72082 | await | 12.1 | Linux | Linux | — | scsi: elx: efct: Fix refcount leak in efct_hw_io_abort() |
| CVE-2026-72087 | await | 12.1 | Linux | Linux | — | scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() |
| CVE-2026-72236 | await | 12.2 | Linux | Linux | — | s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init() |
| CVE-2026-72276 | await | 12.1 | Linux | Linux | — | fbdev: metronomefb: fix potential memory leak in metronomefb_probe() |
| CVE-2026-72306 | await | 12.1 | Linux | Linux | — | vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter |
| CVE-2026-72437 | await | 12.1 | Linux | Linux | — | md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry |
| CVE-2026-15142 | 7.5 | 12.0 | WebCodingPlace | Real Estate Manager Pro | CWE-269 | Real Estate Manager Pro <= 12.8.6 - Authenticated (Subscriber+) Privilege Esc… |
| CVE-2026-72011 | await | 11.8 | Linux | Linux | — | s390/diag: Add missing array_index_nospec() call to memtop_get_page_count() |
| CVE-2026-68469 | await | 11.7 | Linux | Linux | — | wifi: mwifiex: fix permanently busy scans after multiple roam iterations |
| CVE-2026-14229 | 5.3 | 11.6 | Unknown | ECS | CWE-284 | ECS < 4.3.8 - Unauthenticated Private Content Disclosure via ecsload |
| CVE-2026-15948 | 6.4 | 11.5 | themefic | Hydra Booking — Appointment Scheduling & Booking Calendar | CWE-79 | Hydra Booking <= 1.2.2 - Authenticated (Host+) Stored Cross-Site Scripting vi… |
| CVE-2026-19904 | 1.9 | 11.5 | SourceCodester | Online Book Store System | CWE-79 | SourceCodester Online Book Store System System Settings index.php site_settin… |
| CVE-2026-68475 | await | 11.5 | Linux | Linux | — | reset: sunxi: fix memory region leak on ioremap failure |
| CVE-2026-68478 | await | 11.5 | Linux | Linux | — | memstick: ms_block: reject a card that reports too many blocks |
| CVE-2026-72004 | await | 11.5 | Linux | Linux | — | wifi: mac80211: fix memory leak in ieee80211_register_hw() |
| CVE-2026-72010 | await | 11.5 | Linux | Linux | — | cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed |
| CVE-2026-72022 | await | 11.5 | Linux | Linux | — | llc: fix SAP refcount leak in llc_ui_autobind() |
| CVE-2026-72025 | await | 11.5 | Linux | Linux | — | s390/monwriter: Reject buffer reuse with different data length |
| CVE-2026-72038 | await | 11.5 | Linux | Linux | — | net: liquidio: fix BAR resource leak on PF number failure |
| CVE-2026-72039 | await | 11.5 | Linux | Linux | — | bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp() |
| CVE-2026-72047 | await | 11.5 | Linux | Linux | — | ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit |
| CVE-2026-72048 | await | 11.5 | Linux | Linux | — | ieee802154: ca8210: fix cas_ctl leak on spi_async failure |
| CVE-2026-72088 | await | 11.5 | Linux | Linux | — | scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path |
| CVE-2026-72138 | await | 11.5 | Linux | Linux | — | xen/gntdev: fix error handling in ioctl |
| CVE-2026-72140 | await | 11.5 | Linux | Linux | — | i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() |
| CVE-2026-72153 | await | 11.5 | Linux | Linux | — | irqchip/crossbar: Use correct index in crossbar_domain_free() |
| CVE-2026-72159 | await | 11.5 | Linux | Linux | — | ocfs2: reject non-inline dinodes with i_size and zero i_clusters |
| CVE-2026-72163 | await | 11.5 | Linux | Linux | — | ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits |
| CVE-2026-72182 | await | 11.5 | Linux | Linux | — | power: supply: charger-manager: fix refcount leak in is_full_charged() |
| CVE-2026-72215 | await | 11.5 | Linux | Linux | — | MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf() |
| CVE-2026-72218 | await | 11.5 | Linux | Linux | — | lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure |
| CVE-2026-72219 | await | 11.5 | Linux | Linux | — | lockd: Plug nlm_file leak when nlm_do_fopen() fails |
| CVE-2026-72228 | await | 11.5 | Linux | Linux | — | batman-adv: frag: fix primary_if leak on failed linearization |
| CVE-2026-72229 | await | 11.5 | Linux | Linux | — | batman-adv: clean untagged VLAN on netdev registration failure |
| CVE-2026-72230 | await | 11.5 | Linux | Linux | — | batman-adv: frag: free unfragmentable packet |
| CVE-2026-72238 | await | 11.5 | Linux | Linux | — | x86/boot: Validate console=uart8250 baud rate to fix early boot hang |
| CVE-2026-72240 | await | 11.5 | Linux | Linux | — | mfd: sm501: Fix reference leak on failed device registration |
| CVE-2026-72241 | await | 11.5 | Linux | Linux | — | leds: uleds: Fix potential buffer overread |
| CVE-2026-72256 | await | 11.5 | Linux | Linux | — | netfilter: xt_cluster: reject template conntracks in hash match |
| CVE-2026-72260 | await | 11.5 | Linux | Linux | — | ASoC: mediatek: mt8192: Check runtime resume during probe |
| CVE-2026-72264 | await | 11.5 | Linux | Linux | — | fbdev: tridentfb: fix potential memory leak in trident_pci_probe() |
| CVE-2026-72265 | await | 11.5 | Linux | Linux | — | fbdev: nvidia: fix potential memory leak in nvidiafb_probe() |
| CVE-2026-72267 | await | 11.5 | Linux | Linux | — | fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() |
| CVE-2026-72268 | await | 11.5 | Linux | Linux | — | fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() |
| CVE-2026-72269 | await | 11.5 | Linux | Linux | — | fbdev: uvesafb: fix potential memory leak in uvesafb_probe() |
| CVE-2026-72270 | await | 11.5 | Linux | Linux | — | fbdev: s3fb: fix potential memory leak in s3_pci_probe() |
| CVE-2026-72271 | await | 11.5 | Linux | Linux | — | fbdev: i740fb: fix potential memory leak in i740fb_probe() |
| CVE-2026-72272 | await | 11.5 | Linux | Linux | — | fbdev: radeon: fix potential memory leak in radeonfb_pci_register() |
| CVE-2026-72401 | await | 11.4 | Linux | Linux | — | bpf: Fix insn_aux_data leak on verifier err_free_env path |
| CVE-2026-72428 | await | 11.5 | Linux | Linux | — | bpf: Fix stack slot index in nospec checks |
| CVE-2026-72433 | await | 11.5 | Linux | Linux | — | netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak |
| CVE-2026-72479 | await | 11.5 | Linux | Linux | — | iio: accel: mma8452: handle I2C read error(s) in mma8452_read() |
| CVE-2026-72481 | await | 11.5 | Linux | Linux | — | iio: magnetometer: ak8975: fix potential kernel stack memory leak |
| CVE-2026-72484 | await | 11.5 | Linux | Linux | — | staging: most: video: avoid double free on video register failure |
| CVE-2026-74284 | await | 11.5 | Linux | Linux | — | net/sched: sch_hfsc: Don't make class passive twice |
| CVE-2026-72062 | await | 11.3 | Linux | Linux | — | gpio: mt7621: avoid corruption of shared interrupt trigger state |
| CVE-2026-72063 | await | 11.3 | Linux | Linux | — | gpio: tegra: do not call pinctrl for GPIO direction |
| CVE-2026-72070 | await | 11.3 | Linux | Linux | — | wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() |
| CVE-2026-72077 | await | 11.3 | Linux | Linux | — | Input: ims-pcu - fix firmware leak in async update |
| CVE-2026-72308 | await | 11.3 | Linux | Linux | — | mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() |
| CVE-2026-72324 | await | 11.3 | Linux | Linux | — | gpio: mvebu: free generic chips on unbind |
| CVE-2026-72325 | await | 11.3 | Linux | Linux | — | perf/x86/amd/core: Avoid enabling BRS from the SVM reload path |
| CVE-2026-72327 | await | 11.3 | Linux | Linux | — | drm/v3d: Reject invalid indirect BO handle in indirect CSD setup |
| CVE-2026-72333 | await | 11.3 | Linux | Linux | — | Bluetooth: L2CAP: fix tx ident leak for commands without a response |
| CVE-2026-72361 | await | 11.3 | Linux | Linux | — | drm/xe/hw_engine: Fix double-free of managed BO in error path |
| CVE-2026-72376 | await | 11.3 | Linux | Linux | — | afs: Fix misplaced inc of net->cells_outstanding |
| CVE-2026-72379 | await | 11.3 | Linux | Linux | — | fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid |
| CVE-2026-72474 | await | 11.3 | Linux | Linux | — | dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor |
| CVE-2026-73055 | 9.3 | 11.1 | ericcornelissen | shescape | CWE-116 | Shescape before 2.1.15 Home Directory Disclosure via BusyBox |
| CVE-2026-72321 | await | 11.0 | Linux | Linux | — | ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer() |
| CVE-2026-72341 | await | 11.0 | Linux | Linux | — | net/mlx5e: Fix publication race for priv->channel_stats[] |
| CVE-2026-72365 | await | 11.0 | Linux | Linux | — | netfs: Fix writethrough to use collection offload |
| CVE-2026-72060 | await | 11.0 | Linux | Linux | — | net: ethernet: ti: icssg: guard PA stat lookups |
| CVE-2026-72092 | await | 11.0 | Linux | Linux | — | accel/amdxdna: reject command submission on devices without a submit op |
| CVE-2026-72152 | await | 10.9 | Linux | Linux | — | tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() |
| CVE-2026-72155 | await | 10.9 | Linux | Linux | — | mtd: spi-nor: swp: Improve locking user experience |
| CVE-2026-72166 | await | 10.9 | Linux | Linux | — | net/9p: fix infinite loop in p9_client_rpc on fatal signal |
| CVE-2026-72179 | await | 10.9 | Linux | Linux | — | riscv: cacheinfo: Fix node reference leak in populate_cache_leaves |
| CVE-2026-72363 | await | 11.0 | Linux | Linux | — | netfs: Fix folio state after ENOMEM whilst under writeback iteration |
| CVE-2026-72384 | await | 10.9 | Linux | Linux | — | irqchip/ts4800: Fix missing chained handler cleanup on remove |
| CVE-2026-72392 | await | 10.9 | Linux | Linux | — | ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump |
| CVE-2026-72445 | await | 11.0 | Linux | Linux | — | ALSA: usb-audio: qcom: clear opened when stream enable fails |
| CVE-2026-72457 | await | 11.0 | Linux | Linux | — | apparmor: fail policy unpack on accept2 allocation failure |
| CVE-2026-72013 | await | 10.9 | Linux | Linux | — | riscv: Prevent NULL pointer dereference in machine_kexec_prepare() |
| CVE-2026-72037 | await | 10.9 | Linux | Linux | — | net: lan743x: Initialize eth_syslock spinlock before use |
| CVE-2026-72086 | await | 10.9 | Linux | Linux | — | scsi: xen: scsiback: Free the command tag on the TMR submit-failure path |
| CVE-2026-72097 | await | 10.9 | Linux | Linux | — | dm-verity: fix a possible NULL pointer dereference |
| CVE-2026-72156 | await | 10.9 | Linux | Linux | — | fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() |
| CVE-2026-72161 | await | 10.9 | Linux | Linux | — | ocfs2: add journal NULL check in ocfs2_checkpoint_inode() |
| CVE-2026-72167 | await | 10.9 | Linux | Linux | — | mtd: rawnand: pl353: fix probe resource allocation |
| CVE-2026-72177 | await | 10.9 | Linux | Linux | — | mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs() |
| CVE-2026-72193 | await | 10.9 | Linux | Linux | — | ntfs3: cap RESTART_TABLE free-chain walker at rt->used |
| CVE-2026-72214 | await | 10.9 | Linux | Linux | — | power: supply: cpcap-battery: Fix missing nvmem_device_put() causing referenc… |
| CVE-2026-72257 | await | 10.9 | Linux | Linux | — | ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback |
| CVE-2026-72274 | await | 10.9 | Linux | Linux | — | fbdev: hecubafb: fix potential memory leak in hecubafb_probe() |
| CVE-2026-72275 | await | 10.9 | Linux | Linux | — | fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() |
| CVE-2026-72290 | await | 10.9 | Linux | Linux | — | KVM: s390: pci: Fix GISC refcount leak on AIF enable failure |
| CVE-2026-72391 | await | 10.9 | Linux | Linux | — | net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy |
| CVE-2026-72467 | await | 10.9 | Linux | Linux | — | xprtrdma: Check frwr_wp_create() during connect |
Results continue: ranks 401–926.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-15 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.